Skip to main content
RiskZeroCertifiers

Alongside any audit

Integrated audits: ISO 27701 and ISO 22301

One audit program covering ISO 27001 alongside ISO/IEC 27701 privacy or ISO 22301 business continuity.

Typical duration

Combined audit time is lower than separate audits, typically 15 to 25 percent

Request a quote

Fixed fee, reply within two business days.

Why integrate

Management systems built on the ISO harmonized structure share the same clauses for context, leadership, planning, support, operation, evaluation, and improvement. Auditing them separately means covering the same ground twice with different auditors on different dates. An integrated audit examines the shared clauses once and then addresses the requirements specific to each standard.

ISO/IEC 27701: privacy information management

ISO/IEC 27701 adds requirements and controls for organizations acting as personal data controllers, processors, or both. It provides a structured way to demonstrate privacy governance that maps to GDPR, UK GDPR, CCPA, and similar laws, without being tied to any one of them.

An integrated ISO 27001 and ISO 27701 audit covers:

  • Extended ISMS requirements for privacy, including privacy-specific risk assessment
  • Additional guidance on ISO 27001 Annex A controls for privacy
  • Controller-specific controls: lawful basis, consent, data subject rights, transparency
  • Processor-specific controls: customer instructions, sub-processor management, breach notification
  • Privacy by design and data minimization in development and operations

ISO 22301: business continuity management

ISO 22301 sets requirements for a business continuity management system: understanding what must not stop, planning how to keep it running, and testing that the plans work. It sits naturally beside ISO 27001, which already requires ICT readiness for business continuity and incident response.

An integrated ISO 27001 and ISO 22301 audit covers:

  • Business impact analysis and risk assessment for disruption
  • Continuity strategies and solutions, and how they were selected
  • Business continuity plans and procedures, including communication
  • Exercise and test programs, and what they showed
  • Links between security incident management and continuity response

How it works in practice

We build a single audit plan that lists which requirements of each standard are covered in each session. Interviews with leadership, HR, and IT operations cover all standards at once. The report is consolidated, with findings tagged to the standard and clause they relate to. Separate certificates are issued for each standard so you can share whichever one a customer asks for.

Questions

Common questions about integrated audits: iso 27701 and iso 22301

Can ISO 27701 be certified on its own?
No. ISO/IEC 27701 extends ISO/IEC 27001 with privacy-specific requirements and controls, so certification requires a certified ISO 27001 ISMS. Most organizations add it at a surveillance or recertification audit, or at the same time as initial ISO 27001 certification.
Does ISO 22301 require ISO 27001?
No. ISO 22301 is a standalone business continuity management standard. Many organizations already cover business continuity in their ISMS under the ISO 27001 controls for ICT readiness, so extending to a full ISO 22301 certification is a natural step.
Will there be one auditor or several?
One audit team, led by a lead auditor qualified for ISO 27001. Where the team needs additional competence for privacy or continuity, we add a second auditor for the relevant parts of the plan rather than running a separate audit.

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.